First published: Tue Mar 13 2018(Updated: )
Teluu PJSIP version 2.7.1 and earlier contains a Integer Overflow vulnerability in pjmedia SDP parsing that can result in Crash. This attack appear to be exploitable via Sending a specially crafted message. This vulnerability appears to have been fixed in 2.7.2.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Teluu PJSIP | <=2.7.1 | |
Debian Debian Linux | =9.0 | |
debian/pjproject |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1000098 is high with a severity value of 7.5.
CVE-2018-1000098 can be exploited by sending a specially crafted message.
The vulnerability CVE-2018-1000098 has been fixed in version 2.7.2 of Teluu PJSIP.
Teluu PJSIP versions 2.7.1 and earlier are affected by CVE-2018-1000098.
Yes, you can find references for CVE-2018-1000098 at http://downloads.asterisk.org/pub/security/AST-2018-002.html, https://trac.pjsip.org/repos/ticket/2093, and https://security-tracker.debian.org/tracker/CVE-2018-1000098.